Abstract
Since the emergence of intrusion detection systems (IDS) were developed to identify, and to report attacks in computer systems and networks, or against information systems in general, it has always been difficult to provide provably secure information systems that are maintained in a constant secure state throughout their operations. Therefore, the task of intrusion-detection systems is to monitor the usage of such systems, and to detect the apparition of insecure states through out their existence, in order to avoid serious disruption to network services. As a result of the above, we have propose to research and implement a framework that will accomplish our purpose of devising a complete packet scan engine, and evaluate the efficiency of our approach and algorithm, by conducting a wide range of data captured from the university campus. The result of these analyses will be used to investigate the possibility of determining the number of packets that can be verified by the packet scan engine, in order to reduce the cost of scanning the packets that pass through both SNORT and Bro rules. With this framework, large scale or co-ordinate anomalies can be detected in real time.